New LockBit Ransomware Uses Self-Spreading Automation to Rapidly Encrypt Networks

A relatively new ransomware strain named LockBit relies on highly automated, self-spreading features to ravage corporate networks in just hours instead of weeks. The malware exploits weak administrative passwords and missing multi-factor authentication to quickly lock down victim data.

A new ransomware-as-a-service threat known as LockBit demonstrates how automation drastically speeds up network infiltration and data encryption. Unlike competitors that require human hackers to spend days or weeks manually surveying a target network, LockBit spreads entirely on its own and completes its attack in just a few hours.

The attack profile documented by McAfee and Northwave shows that attackers gain initial access by guessing weak passwords on administrative accounts that lack multi-factor authentication. Once inside, the ransomware uses ARP tables and other automated techniques to map out the local network and independently propagate to all connected systems without human guidance.

This highly efficient approach leaves victimized organizations with almost no time to detect or stop the attack, often forcing them to pay the ransom to regain access to their files. Security researchers note that LockBit is actively targeting large organizations across the US, the UK, France, Germany, China, India, and other nations, making it a significant and growing threat.

Read More at the original source →